openqareer

Application Security Engineer

Ebizolution · Makati

# Application Security Engineer **Ebizolution** · Makati · `On-site` 🕒 **Статус:** *Опубликовано: 19 дней назад* · *Источник: Indeed* --- ### About the Role PRIMARY RESPONSIBILITIES: Vulnerability Scanning & Triage Execute and manage daily Application Security testing routines, utilizing Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools. Triage scan results to identify true positive vulnerabilities, filter out false positives, and appropriately risk-score findings based on business impact. Secure Code Review & Testing Perform manual secure code reviews and targeted penetration testing on critical web and mobile applications to identify complex logic flaws that automated tools might miss. Assist the Lead Application Security Engineer in conducting threat modeling exercises for new applications and features. Developer Support & Remediation Serve as the primary technical resource for software developers, providing clear, actionable guidance and code-level recommendations to remediate identified security vulnerabilities. Validate that implemented fixes effectively resolve the underlying security issues without introducing new flaws. DevSecOps Integration Maintain and optimize the integration of automated security scanning tools within the organization's CI/CD pipelines to support a seamless Secure SDLC. PRIMARY DAY TO DAY DUTIES Review the daily output from SAST, DAST, and SCA tools, logging validated vulnerabilities into the development team's ticketing system. Participate in a morning sync with the Lead Application Security Engineer to review the status of high-priority vulnerabilities and assign daily testing tasks. Meet directly with software developers to explain the mechanics of identified vulnerabilities (like SQL Injection or Cross-Site Scripting) and assist them in writing secure replacement code. Update and maintain the application vulnerability tracking dashboard, ensuring remediation efforts are progressing within established SLAs. Conduct ad-hoc security assessments on third-party libraries or open-source components before they are approved for use in enterprise applications. Assist in updating internal secure coding guidelines and standard operating procedures (SOPs). JOB SPECIFICATION: Academic Qualification: A Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, Information Systems, or any related technical discipline. Skills: Strong understanding of application security principles, the OWASP Top 10, and common software vulnerabilities. Hands-on proficiency with application security testing tools. Solid programming and scripting skills in one or more common languages (e.g., Java, C#, Python, JavaScript/Node.js) to effectively review and understand developer code. Familiarity with CI/CD pipelines and modern software development methodologies. Excellent analytical and problem-solving skills to trace vulnerabilities from dynamic execution back to the source code. Strong interpersonal and communication skills to effectively collaborate with and guide software developers without causing friction. Work Experience: Progressive experience in software development, software engineering, or IT security. At least 2 years of dedicated, hands-on experience in an Application Security role, performing code reviews, vulnerability triaging, or penetration testing. Proven background in working closely with development teams to remediate security flaws in a fast-paced environment. Work Location: In person

Наблюдалась 2026-09-16, впервые 2026-08-28, источник — Indeed.

Открыть у работодателя